Additional Microsoft Entra services and features related to identity, access, and network security
Third-party Windows MDM: How do we get the Entra Device ID in the v2 access token sent during MDM enrollment?
We are implementing a third-party MDM that uses the Windows MDM enrollment protocol and integrates with Microsoft Entra. During automatic MDM enrollment, Windows sends an Entra access token to our enrollment endpoint. With a v1 token we can obtain the device ID claim, but with the v2 token we are receiving, the device ID is absent. Is there a supported way for a third-party MDM application to configure/request the v2 token so that it contains the Entra device ID (deviceid claim)? If not, what is the supported mechanism for associating the enrollment request with the Entra device object?
Adding deviceid as an optional claim appears to work, even though it shows a yellow warning sign.